CVE-2023-37551

CVE-2023-37551

In multiple Codesys products in multiple versions, after successful authentication as a user, specially crafted network communication requests can utilize the CmpApp component to download files with any file extensions to the controller. In contrast to the regular file download via CmpFileTransfer, no filtering of certain file types is performed here. As a result, the integrity of the CODESYS control runtime system may be compromised by the files loaded onto the controller.

Source: CVE-2023-37551

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다